kcode-k1-web-podman 0.1.4

Fresh rootless Podman execution leaf for one K1 Web check.
Documentation
# Consumer contract

```rust
#[derive(Clone)]
pub struct WebPodmanConfig {
    pub podman: PathBuf, pub image: String, pub checker: PathBuf, pub chromium: PathBuf,
    pub chromium_version: String, pub cpu_millis: u32, pub memory_bytes: u64, pub pids_limit: u32,
    pub tmpfs_bytes: u64, pub shm_bytes: u64,
    pub checker_timeout: Duration, pub wall_timeout: Duration,
}
pub struct CheckInput {
    pub candidate: WebIdInput, pub candidate_root: PathBuf, pub projection_root: PathBuf,
    pub entry: String, pub tests: String, pub selections: Vec<SelectionInput>,
}
pub struct CommandDiagnostics { pub status: ExitStatus, pub stdout: Vec<u8>, pub stderr: Vec<u8> }
pub struct CheckOutput { pub diagnostics: CommandDiagnostics, pub report: Report }
pub enum WebPodmanError {
    InvalidInput { field: &'static str, reason: String }, Spawn(io::Error), Process(String),
    Timeout { diagnostics: CommandDiagnostics, kill_failure: Option<String> },
    Infrastructure { diagnostics: CommandDiagnostics, report: Option<Box<Report>>, reason: String },
}
pub fn WebPodman::new(config: WebPodmanConfig) -> Result<WebPodman, WebPodmanError>;
pub fn WebPodman::checker_digest(&self) -> &str; pub fn WebPodman::image_identity(&self) -> &str;
pub fn WebPodman::image_digest(&self) -> &str; pub fn WebPodman::chromium_version(&self) -> &str;
pub fn WebPodman::command_policy_identity(&self) -> &str; pub fn WebPodman::frozen_command_policy_identity(&self) -> &str;
pub fn WebPodman::check(&self, input: CheckInput) -> Result<CheckOutput, WebPodmanError>;
pub fn WebPodman::check_frozen(&self, input: CheckInput, public_projection_root: impl AsRef<Path>) -> Result<CheckOutput, WebPodmanError>;
```

This synchronous leaf runs one K1 Web check in one fresh rootless Podman container. It owns no retry, cache, publication, access decision, image build or pull, browser behavior, durable state, or network work beyond the local Podman process.

Configuration requires canonical absolute nonsymlink Podman/checker executables, one nonempty ordinary image reference, a normalized absolute in-image Chromium path, nonempty claimed Chromium version, and positive whole-millisecond checker/wall deadlines. The wall deadline may equal but not precede the checker deadline. CPU, memory, PID, tmpfs-size and shared-memory-size values are optional: zero applies no explicit limit for that resource; nonzero values retain the corresponding Podman flag. `/tmp` remains a private writable tmpfs even when its size is not explicitly capped.

`checker_digest` hashes the exact mounted checker. `image_identity` returns the configured image reference. `image_digest` returns an actual canonical digest when the reference contains one, otherwise a deterministic SHA-256 cache identity over the ordinary image reference; it does not pin or inspect the image. Command-policy identities bind the complete effective command, mounts, Chromium path and deadlines.

Each check rehashes the checker and rejects changed bytes. `check` routes its projection at `/k1/input/public`. `check_frozen` routes the admitted view at `/k1/input/admitted` and separately mounts the live public projection at `/k1/input/public`. Mounted paths must not overlap.

A call starts one `podman --remote=false run --interactive` with no retry, attaching the encoded checker request to the container’s standard input. The container is removed, offline, read-only, caller-mapped, capability-free and no-new-privileges. Candidate, projection and checker mounts are read-only. Complete output is retained; the wall deadline kills and reaps the process group. A canonical report is accepted only for exit 0 with success or exit 1 with completed failure.